cbcvebase.
CVE-2011-1024
published 2011-03-20

CVE-2011-1024: chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka…

PriorityP432medium4.6CVSS 2.0
AVNACHAuSCPIPAP
EPSS
2.96%
85.7th percentile
chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianopenldap< openldap 2.4.25-1 (bookworm)openldap 2.4.25-1 (bookworm)
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap
openldapopenldap>= 0 < 2.4.25-12.4.25-1
openldapopenldap>= 0 < 2.4.25-12.4.25-1
openldapopenldap>= 0 < 2.4.25-12.4.25-1
openldapopenldap>= 0 < 2.4.25-12.4.25-1

CVSS provenance

nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.